All skills
aws avatar

/amazon-opensearch-service

@04f39cf

Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration (Solr/ES/self-managed into AOS/AOSS, schema/query translation, sizing, cutover); provisioning (domain + AOSS lifecycle, upgrades, FGAC, monitoring); search (vector / semantic / hybrid / RAG with Bedrock); log-analytics (PPL, OSI, anomaly detection, Dashboards); trace-analytics (OTel spans, service maps, Data Prepper); ai-assistant (natural language data exploration, incident investigation, root cause analysis). Triggers on OpenSearch, AOS, AOSS, Elasticsearch, Solr, vector/k-NN/semantic/hybrid search, RAG, log analytics, PPL, trace analytics, ISM, FAISS, HNSW, Migration Assistant, UltraWarm, OR1, query my data, analyze logs, investigate errors, root cause analysis.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/amazon-opensearch-service

This session only. Nothing lands on disk.

referencesprovisioning-domain-deploy-search.md

≈562 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Amazon OpenSearch Service Domain — Deploy Search Configuration

Deploy index configuration, ML models, and pipelines to a provisioned domain.

Step 1: Migrate Index Configuration

Create the index with mappings from local setup:

PUT <domain-endpoint>/<index-name>
{
  "settings": { ... },
  "mappings": { ... }
}

Configure replicas (1-2) for high availability.

Step 2: Deploy ML Models (semantic/hybrid search)

Pretrained models from OpenSearch repository:

POST <domain-endpoint>/_plugins/_ml/models/_register?deploy=true
{
  "name": "huggingface/sentence-transformers/all-MiniLM-L12-v2",
  "version": "1.0.1",
  "model_format": "TORCH_SCRIPT"
}

Remote Bedrock models:

See provisioning-agentic-setup.md Steps 1-2 for IAM role and connector setup pattern.

Test inference:

POST <domain-endpoint>/_plugins/_ml/models/<model-id>/_predict
{ "parameters": { "inputText": "hello world" } }

Step 3: Create Ingest Pipelines

PUT <domain-endpoint>/_ingest/pipeline/<pipeline-name>
{
  "description": "Embedding pipeline",
  "processors": [{
    "text_embedding": {
      "model_id": "<model_id>",
      "field_map": { "<text-field>": "<vector-field>" }
    }
  }]
}

Attach to index:

PUT <domain-endpoint>/<index-name>/_settings
{ "index.default_pipeline": "<pipeline-name>" }

Step 4: Create Search Pipelines (hybrid search)

PUT <domain-endpoint>/_search/pipeline/<search-pipeline-name>
{
  "phase_results_processors": [{
    "normalization-processor": {
      "normalization": { "technique": "min_max" },
      "combination": { "technique": "arithmetic_mean", "parameters": { "weights": [0.3, 0.7] } }
    }
  }]
}

Step 5: Index Sample Documents & Test

Index test documents and verify pipeline processing with appropriate search queries.

Next Step

Security Considerations

  • Ensure encryption at rest is enabled on the domain before deploying ML models or embedding pipelines
  • Enable CloudTrail to audit model deployments and data access
  • Enforce HTTPS for all API operations

Source: SKILL.md on GitHub

No alerts28d3 checks · Risk SAFE
  • Gen Agent Trust Hub28d

    This skill is a highly structured and security-conscious guide for managing Amazon OpenSearch Service and Serverless. It provides comprehensive instructions for migrations, provisioning, and analytics while strictly adhering to AWS security best practices, such as using SigV4 signing, IAM least-privilege, and AWS Secrets Manager for credential handling.

  • Socket28d

    No alerts

  • Snyk28d

    Risk: LOW · No issues

Signed by skilld at 04f39cf. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/amazon-opensearch-service